<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" nvd_xml_version="2.0" pub_date="2009-11-07T06:05:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-2009-3611">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:le-web:backintime:0.9.26" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:le-web:backintime:0.9.26</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3611</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T12:30:00.890-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-26T19:20:30.187-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-26T19:01:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz">http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=289047">http://bugs.gentoo.org/show_bug.cgi?id=289047</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.html">FEDORA-2009-9298</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.html">FEDORA-2009-9282</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=520210">https://bugzilla.redhat.com/show_bug.cgi?id=520210</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256">https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125554894700336&amp;w=2">[oss-security] 20091014 Re: CVE Request - backintime</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125553645511436&amp;w=2">[oss-security] 20091014 CVE Request - backintime</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785</vuln:reference>
        </vuln:references>
        <vuln:summary>common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3625">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sahana:sahana:0.6.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sahana:sahana:0.6.2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3625</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T12:30:00.953-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:23:29.390-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-26T19:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=530255">https://bugzilla.redhat.com/show_bug.cgi?id=530255</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/10/22/6">[oss-security] 20091022 Re: CVE Request -- Sahana</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/10/22/3">[oss-security] 20091022 CVE Request -- Sahana</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sahana.cvs.sourceforge.net/viewvc/sahana/sahana-phase2/www/index.php?r1=1.83&amp;r2=1.84">http://sahana.cvs.sourceforge.net/viewvc/sahana/sahana-phase2/www/index.php?r1=1.83&amp;r2=1.84</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://fedorahosted.org/rel-eng/ticket/2635">https://fedorahosted.org/rel-eng/ticket/2635</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36826">36826</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/mailarchive/forum.php?thread_name=5d9043b70910191044l4bb0178fs563a5128a0f5db01%40mail.gmail.com&amp;forum_name=sahana-maindev">[sahana-maindev] 20091019 SEVERE Security Vulnerability in Sahana Identified and Patched</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3778">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:adam_gerson:moodle_courselist:6.x-1.2:beta1" />
                    <cpe-lang:fact-ref name="cpe:/a:adam_gerson:moodle_courselist:6.x-1.2:beta2" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:adam_gerson:moodle_courselist:6.x-1.2:beta2</vuln:product>
            <vuln:product>cpe:/a:adam_gerson:moodle_courselist:6.x-1.2:beta1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3778</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.360-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T10:57:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3001">ADV-2009-3001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36787">36787</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610986">http://drupal.org/node/610986</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53895">moodle-course-unspecified-sql-injection(53895)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37126">37126</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59100">59100</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3779">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:6.x-1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:6.x-1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:6.x-1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:6.x-1.x-dev" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:5.x-1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:5.x-1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:5.x-1.3" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:5.x-1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stefan_auditor:vcard:5.x-1.x-dev" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:stefan_auditor:vcard:5.x-1.0</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:5.x-1.3</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:5.x-1.2</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:5.x-1.1</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:6.x-1.x-dev</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:5.x-1.x-dev</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:6.x-1.2</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:6.x-1.1</vuln:product>
            <vuln:product>cpe:/a:stefan_auditor:vcard:6.x-1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3779</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.377-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T16:16:29.843-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:04:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3002">ADV-2009-3002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610996">http://drupal.org/node/610996</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610420">http://drupal.org/node/610420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610416">http://drupal.org/node/610416</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53903">vcard-themevcard-xss(53903)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36789">36789</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37127">37127</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3780">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:ashok_modi:abuse:5.x-2.x-dev" />
                    <cpe-lang:fact-ref name="cpe:/a:ashok_modi:abuse:5.x-1.0:beta" />
                    <cpe-lang:fact-ref name="cpe:/a:ashok_modi:abuse:5.x-1.x-dev" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ashok_modi:abuse:5.x-2.x-dev</vuln:product>
            <vuln:product>cpe:/a:ashok_modi:abuse:5.x-1.0:beta</vuln:product>
            <vuln:product>cpe:/a:ashok_modi:abuse:5.x-1.x-dev</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3780</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.407-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T16:25:15.390-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:15:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36791">36791</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/611078">http://drupal.org/node/611078</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610900">http://drupal.org/node/610900</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610784">http://drupal.org/node/610784</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53898">abuse-unspecified-xss(53898)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37129">37129</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1 and 6.x before 6.x-1.1-alpha1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3781">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:quicksketch:filefield:6.x-3.1" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:quicksketch:filefield:6.x-3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3781</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.420-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T16:35:15.967-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:25:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36792">36792</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/611128">http://drupal.org/node/611128</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/609874">http://drupal.org/node/609874</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/516104">http://drupal.org/node/516104</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/files/issues/filefield-node-access-fix-516104-3.patch">http://drupal.org/files/issues/filefield-node-access-fix-516104-3.patch</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53897">filefield-nodeaccess-security-bypass(53897)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37130">37130</vuln:reference>
        </vuln:references>
        <vuln:summary>The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3782">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:2bits:userpoints:6.x-1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:2bits:userpoints:6.x-1.x-dev" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:2bits:userpoints:6.x-1.0</vuln:product>
            <vuln:product>cpe:/a:2bits:userpoints:6.x-1.x-dev</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3782</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.453-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T16:44:40.203-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>3.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:36:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/2998">ADV-2009-2998</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36786">36786</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610828">http://drupal.org/node/610828</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610818">http://drupal.org/node/610818</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53896">userpoints-userpoint-information-disclosure(53896)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37123">37123</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59124">59124</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3783">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.x-dev" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.x-dev</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.2</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.1</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3783</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.467-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T16:53:47.280-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36790">36790</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/611002">http://drupal.org/node/611002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/590098">http://drupal.org/node/590098</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53905">simplenews-unspecified-xss(53905)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37128">37128</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3784">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.x-dev" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.x-dev</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.2</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.1</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3784</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.500-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:53:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36790">36790</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/611002">http://drupal.org/node/611002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/590098">http://drupal.org/node/590098</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37128">37128</vuln:reference>
        </vuln:references>
        <vuln:summary>Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3785">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.x-dev" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.x-dev</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.2</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.1</vuln:product>
            <vuln:product>cpe:/a:sjoerd_arendsen:simplenews_statistics:6.x-1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3785</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.517-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T16:59:28.670-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:55:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36790">36790</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/611002">http://drupal.org/node/611002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/590098">http://drupal.org/node/590098</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53906">simplenews-unspecified-csrf(53906)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37128">37128</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3786">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:moshe_weitzman:og_vocab:5.x-1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:moshe_weitzman:og_vocab:5.x-1.x-dev" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:drupal:drupal" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:moshe_weitzman:og_vocab:5.x-1.0</vuln:product>
            <vuln:product>cpe:/a:moshe_weitzman:og_vocab:5.x-1.x-dev</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3786</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.547-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T17:27:38.920-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T16:58:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3000">ADV-2009-3000</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36784">36784</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/610948">http://drupal.org/node/610948</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/605094">http://drupal.org/node/605094</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53902">ogvocabulary-title-xss(53902)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37125">37125</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59129">59129</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3787">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vivvo:vivvo:4.1.5.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vivvo:vivvo:4.1.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3787</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.577-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T17:34:36.407-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T17:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.waraxe.us/advisory-75.html">http://www.waraxe.us/advisory-75.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36783">36783</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/507358/100/0/threaded">20091021 [waraxe-2009-SA#075] - Remote File Disclosure in Vivvo CMS 4.1.5.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37117">37117</vuln:reference>
        </vuln:references>
        <vuln:summary>files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3788">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:opendocman:opendocman:1.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:opendocman:opendocman:1.2.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3788</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.593-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:23:42.937-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T17:33:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36777">36777</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53886">opendocman-user-sql-injection(53886)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt">http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30750">30750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59301">59301</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3789">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:opendocman:opendocman:1.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:opendocman:opendocman:1.2.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3789</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.610-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:23:43.063-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T17:36:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36777">36777</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53887">opendocman-multiple-xss(53887)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt">http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30750">30750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59312">59312</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59311">59311</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59310">59310</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59309">59309</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59308">59308</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59307">59307</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59306">59306</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59305">59305</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59304">59304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59303">59303</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59302">59302</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3790">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cutepdf:formmax:3.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:cutepdf:formmax:3.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3790</vuln:cve-id>
        <vuln:published-datetime>2009-10-26T13:30:00.640-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T17:48:17.377-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-27T17:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53890">formmax-aim-bo(53890)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/36943">36943</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59079">59079</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3801">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:opendocman:opendocman:1.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:opendocman:opendocman:1.2.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3801</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.280-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T07:59:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30750">30750</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3802">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.4.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.0.8.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.1.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.0.8.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.0.5</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.4</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.0.7</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.5</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.2.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.2.2</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.2.3</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.4.0.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.3.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3802</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.313-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T08:06:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53894">amiro-index-path-disclosure(53894)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/2967">ADV-2009-2967</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.onsec.ru/vuln?id=12">http://www.onsec.ru/vuln?id=12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37065">37065</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0910-exploits/ONSEC-09-005.txt">http://packetstormsecurity.org/0910-exploits/ONSEC-09-005.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3803">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.4.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:5.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.2.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:amirocms:amiro.cms:4.0.8.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.1.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.0.8.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.0.5</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.4</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.0.7</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.5</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.2.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.2.2</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.2.3</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.4.0.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:4.2.3.0</vuln:product>
            <vuln:product>cpe:/a:amirocms:amiro.cms:5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3803</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.343-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T08:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53893">amiro-loginname-xss(53893)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53892">amiro-statusmessage-xss(53892)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/2967">ADV-2009-2967</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.onsec.ru/vuln?id=11">http://www.onsec.ru/vuln?id=11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37065">37065</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0910-exploits/ONSEC-09-004.txt">http://packetstormsecurity.org/0910-exploits/ONSEC-09-004.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9) blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php, (13) srv_twist_prevention.php, (14) srv_tags.php, (15) srv_tags_reindex.php, (16) google_sitemap.php, (17) sitemap_history.php, (18) srv_options.php, (19) locales.php and (20) plugins_wizard.php in _admin/; a crafted IMG BBcode tag in the message body of a (21) forum, (22) guestbook, or (23) comment; (24) the content of an avatar file, which is not properly handled by Internet Explorer; and (25) the loginname parameter (aka username) in _admin/index.php.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3804">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:2m1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:runcms:runcms:2m1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3804</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.360-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T08:30:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37137">37137</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://retrogod.altervista.org/9sg_runcms_store_sql.html">http://retrogod.altervista.org/9sg_runcms_store_sql.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3805">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:kde-apps:kleopatra:2.0.11" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:gpg4win:gpg4win:2.0.1" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gpg4win:gpg4win:2.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3805</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.407-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T08:35:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53908">gpg4win-gpg2-dos(53908)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36781">36781</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.com/0910-exploits/gpg2kleo-dos.txt">http://www.packetstormsecurity.com/0910-exploits/gpg2kleo-dos.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certificate signature.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3806">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dedecms:dedecms:5.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dedecms:dedecms:5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3806</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.420-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T08:42:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/507109/100/0/threaded">20091012 DEDECMS v5.1 Sql Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3807">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mixvibes:mixvibes:7.043::pro" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mixvibes:mixvibes:7.043::pro</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3807</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.453-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T08:48:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51715">mixvibes-vib-bo(51715)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9147">9147</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3808">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:kramware:mixsense_dj_studio:1.0.0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:kramware:mixsense_dj_studio:1.0.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3808</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.467-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T08:55:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51814">djstudio-mp3-dos(51814)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9178">9178</vuln:reference>
        </vuln:references>
        <vuln:summary>MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an .mp3 playlist file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3809">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:acoustica:mp3_audio_mixer:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:acoustica:mp3_audio_mixer:2.471" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:acoustica:mp3_audio_mixer:1.0</vuln:product>
            <vuln:product>cpe:/a:acoustica:mp3_audio_mixer:2.471</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3809</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.500-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T09:22:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51868">acoustica-m3u-bo(51868)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1958">ADV-2009-1958</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9212">9212</vuln:reference>
        </vuln:references>
        <vuln:summary>Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3810">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:acoustica:mp3_audio_mixer:2.471" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:acoustica:mp3_audio_mixer:2.471</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3810</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.517-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T09:27:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51868">acoustica-m3u-bo(51868)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1958">ADV-2009-1958</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9213">9213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35902">35902</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/56033">56033</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3811">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:assistanttools:music_tag_editor:1.61" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:assistanttools:music_tag_editor:1.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3811</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.547-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T09:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51724">musictageditor-mp3-bo(51724)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9167">9167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35828">35828</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/55861">55861</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://liquidworm.blogspot.com/2009/07/music-tag-editor-161-build-212-remote.html">http://liquidworm.blogspot.com/2009/07/music-tag-editor-161-build-212-remote.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3812">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:otslabs:otsav_dj:1.85.64.0:trial" />
                <cpe-lang:fact-ref name="cpe:/a:otslabs:otsav_radio:1.85.64.0:trial" />
                <cpe-lang:fact-ref name="cpe:/a:otslabs:otsav_tv:1.85.64.0:trial" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:otslabs:otsav_tv:1.85.64.0:trial</vuln:product>
            <vuln:product>cpe:/a:otslabs:otsav_radio:1.85.64.0:trial</vuln:product>
            <vuln:product>cpe:/a:otslabs:otsav_dj:1.85.64.0:trial</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3812</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.563-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T10:45:33.983-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T10:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51628">otsav-multiple-olf-bo(51628)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1861">ADV-2009-1861</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9113">9113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35738">35738</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0907-exploits/otsav-overflow.txt">http://packetstormsecurity.org/0907-exploits/otsav-overflow.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/55747">55747</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3813">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:2m1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:runcms:runcms:2m1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3813</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.593-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T10:48:38.203-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T10:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37137">37137</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://retrogod.altervista.org/9sg_runcms_forum_sql.html">http://retrogod.altervista.org/9sg_runcms_forum_sql.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3814">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:2m1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:runcms:runcms:2m1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3814</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.610-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T10:51:03.063-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T10:47:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://retrogod.altervista.org/9sg_runcms_forum_sql.html">http://retrogod.altervista.org/9sg_runcms_forum_sql.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3815">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:2m1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:runcms:runcms:2m1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3815</vuln:cve-id>
        <vuln:published-datetime>2009-10-27T12:30:00.640-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T10:54:29.563-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T10:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://retrogod.altervista.org/9sg_runcms_forum_sql.html">http://retrogod.altervista.org/9sg_runcms_forum_sql.html</vuln:reference>
        </vuln:references>
        <vuln:summary>RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to modules/contact/index.php or (2) uid[] parameter to userinfo.php, which leaks the installation path in an error message when these parameters are used in a call to the preg_match function.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3816">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_connections:2.5.0.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_connections:2.5.0.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3816</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.610-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T11:00:38.670-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T10:54:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-01.ibm.com/support/docview.wss?uid=swg24024303">http://www-01.ibm.com/support/docview.wss?uid=swg24024303</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37106">37106</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3817">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla%21" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:ordasoft:com_booklibrary:1.0" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ordasoft:com_booklibrary:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3817</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.703-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T11:09:44.827-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T10:58:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/2969">ADV-2009-2969</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36732/exploit">http://www.securityfocus.com/bid/36732/exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36732">36732</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than CVE-2009-2637.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3818">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:typo3:typo3" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.0.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.4.6" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.4.5" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.4.4" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.4.3" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.4.2" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.4.1" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.4.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.3.3" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.3.2" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.3.1" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.3.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.2.3" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.2.2" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.2.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:0.1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:stanislas_rolland:sr_freecap:1.2.0" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.2.3</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.1.0</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.2.2</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.4.0</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.2.0</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.4.2</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.4.1</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.1.1</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.1.2</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.1.0</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.0.0</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.2.0</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.0.1</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.0.2</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.0.3</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:1.0.4</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.4.3</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.4.4</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.4.5</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.4.6</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.3.2</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.3.3</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.3.0</vuln:product>
            <vuln:product>cpe:/a:stanislas_rolland:sr_freecap:0.3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3818</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.750-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T11:29:25.907-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T11:11:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37094">37094</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3819">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:typo3:typo3" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.6.3" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.6.2" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.6.1" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.6.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.1" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.2" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.3" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.4" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.5" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.6" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.7" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.8" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.9" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.10" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.11" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.12" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.13" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.2.14" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.3.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.3.1" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.4.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.4.1" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.5.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.5.3" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.5.4" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.5.5" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.5.6" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.5.7" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.5.8" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:0.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:0.2.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.0.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.1.3" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.1.5" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.1.6" />
                    <cpe-lang:fact-ref name="cpe:/a:urs_maag:maag_randomimage:1.6.4" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:0.2.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.0.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.4.1</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.4.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.1.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.3.1</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.1.1</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.3.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.1.5</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.1.3</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.5.6</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.5.7</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.5.8</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.1.6</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.9</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:0.0.1</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.8</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.7</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.5.3</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.5.4</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.6</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.5.5</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.5</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.4</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.3</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.2</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.5.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.1</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.6.0</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.6.1</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.6.2</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.6.3</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.6.4</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.14</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.10</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.11</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.12</vuln:product>
            <vuln:product>cpe:/a:urs_maag:maag_randomimage:1.2.13</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3819</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.797-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T11:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37095">37095</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3820">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:typo3:typo3" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:flagbit:fb_filebase:0.1.0" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:flagbit:fb_filebase:0.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3820</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.827-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T12:02:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in the Flagbit Filebase (fb_filebase) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3821">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:typo3:typo3" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:apache:solr:1.0.0" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:solr:1.0.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3821</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.843-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T12:11:26.530-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T12:04:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3822">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla%21" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:fijiwebdesign:com_ajaxchat:1.0" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:fijiwebdesign:com_ajaxchat:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3822</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.877-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T12:30:58.703-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T12:13:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/2968">ADV-2009-2968</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36731">36731</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0910-exploits/joomlaajaxchat-rfi.txt">http://www.packetstormsecurity.org/0910-exploits/joomlaajaxchat-rfi.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37087">37087</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3823">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ac4p:mobilelib_gold:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ac4p:mobilelib_gold:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3823</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.890-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T12:30:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51713">mobilelib-myhtml-file-include(51713)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9144">9144</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3824">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:michael_j_greenwood:php_content_manager:0.3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:michael_j_greenwood:php_content_manager:0.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3824</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.907-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T12:47:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51737">greenwood-processor-file-include(51737)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9156">9156</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3825">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:thomas_graber:gencms:2006" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:thomas_graber:gencms:2006</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3825</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T06:30:00.937-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-28T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-28T12:37:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/51653">gencms-show-file-include(51653)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/9103">9103</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admin/pages/SiteNew.php.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3639">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:proftpd:proftpd:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:proftpd:proftpd:1.3.2:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:proftpd:proftpd:1.3.2:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:proftpd:proftpd:1.3.2:rc4" />
                <cpe-lang:fact-ref name="cpe:/a:proftpd:proftpd:1.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:proftpd:proftpd:1.3.2:a" />
                <cpe-lang:fact-ref name="cpe:/a:proftpd:proftpd:1.3.3:rc1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:proftpd:proftpd:1.3.2</vuln:product>
            <vuln:product>cpe:/a:proftpd:proftpd:1.3.2:rc4</vuln:product>
            <vuln:product>cpe:/a:proftpd:proftpd:1.3.1</vuln:product>
            <vuln:product>cpe:/a:proftpd:proftpd:1.3.2:rc2</vuln:product>
            <vuln:product>cpe:/a:proftpd:proftpd:1.3.2:rc1</vuln:product>
            <vuln:product>cpe:/a:proftpd:proftpd:1.3.3:rc1</vuln:product>
            <vuln:product>cpe:/a:proftpd:proftpd:1.3.2:a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3639</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T10:30:00.217-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T08:54:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-310" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=530719">https://bugzilla.redhat.com/show_bug.cgi?id=530719</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36804">36804</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53936">proftpd-modtls-security-bypass(53936)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:288">MDVSA-2009:288</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37131">37131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125632960508211&amp;w=2">[oss-security] 20091023 Re: proftpd - mod_tls - Improper SSL/TLS certificate subjectAltName verification</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125630966510672&amp;w=2">[oss-security] 20091023 proftpd - mod_tls - Improper SSL/TLS certificate subjectAltName verification</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.proftpd.org/show_bug.cgi?id=3275">http://bugs.proftpd.org/show_bug.cgi?id=3275</vuln:reference>
        </vuln:references>
        <vuln:summary>The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3641">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.7" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.4" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.5" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.2" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.3" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.0" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.6" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.0:beta" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.0:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.9.0" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.9.1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.7_beta1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.6.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.6.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.0" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.3" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.3.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.8.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snort:snort:1.8.4</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.3</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.2</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.7</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.6</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.5</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.7_beta1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.6.2</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.6.1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.0:beta</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.3.1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.3.2</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.3.4</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.2.2</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.3.5</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.0</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.9.1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.9.0</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.0</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.3</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.0:rc1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.6</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.6.1.2</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.6.1.1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:2.8.3.4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3641</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T10:30:00.250-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T09:27:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36795">36795</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://vrt-sourcefire.blogspot.com/2009/10/snort-2851-release.html">http://vrt-sourcefire.blogspot.com/2009/10/snort-2851-release.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/fulldisclosure/2009/Oct/299">20091022 Snort &lt;= 2.8.5 IPV6 Remote DoS</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=530863">https://bugzilla.redhat.com/show_bug.cgi?id=530863</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53912">snort-ipv6-dos(53912)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3014">ADV-2009-3014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/59159">59159</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/10/25/5">[oss-security] 20091025 SANS: Security Thought LeadersRe: CVE Request -- Snort - 2.8.5.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1023076">1023076</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37135">37135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125649553414700&amp;w=2">[oss-security] 20091025 CVE Request -- Snort - 2.8.5.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://dl.snort.org/snort-current/release_notes_2851.txt">http://dl.snort.org/snort-current/release_notes_2851.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3700">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squidguard:squidguard:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:squidguard:squidguard:1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squidguard:squidguard:1.4</vuln:product>
            <vuln:product>cpe:/a:squidguard:squidguard:1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3700</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T10:30:00.267-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T10:07:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3013">ADV-2009-3013</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091015">http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36800">36800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53921">squidguard-sglog-security-bypass(53921)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/507440/100/0/threaded">20091026 squidGuard 1.3 &amp; 1.4 : buffer overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/59163">59163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1023079">1023079</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37107">37107</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode."</vuln:summary>
    </entry>
    <entry id="CVE-2009-3826">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squidguard:squidguard:1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squidguard:squidguard:1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3826</vuln:cve-id>
        <vuln:published-datetime>2009-10-28T10:30:00.297-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T10:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3013">ADV-2009-3013</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36800">36800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53922">squidguard-url-security-bypass(53922)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091019">http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091019</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/507440/100/0/threaded">20091026 squidGuard 1.3 &amp; 1.4 : buffer overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/59164">59164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1023079">1023079</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37107">37107</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.</vuln:summary>
    </entry>
    <entry id="CVE-2009-1563">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-1563</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.687-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T12:12:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-59.html">http://www.mozilla.org/security/announce/2009/mfsa2009-59.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=516862">https://bugzilla.mozilla.org/show_bug.cgi?id=516862</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=516396">https://bugzilla.mozilla.org/show_bug.cgi?id=516396</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/secunia_research/2009-35/">http://secunia.com/secunia_research/2009-35/</vuln:reference>
        </vuln:references>
        <vuln:summary>Array index error in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows remote attackers to execute arbitrary code via a long string that triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3370">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3370</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.767-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T12:18:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-52.html">http://www.mozilla.org/security/announce/2009/mfsa2009-52.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=511615">https://bugzilla.mozilla.org/show_bug.cgi?id=511615</vuln:reference>
        </vuln:references>
        <vuln:summary>Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3371">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3371</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.860-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T12:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-54.html">http://www.mozilla.org/security/announce/2009/mfsa2009-54.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=514554">https://bugzilla.mozilla.org/show_bug.cgi?id=514554</vuln:reference>
        </vuln:references>
        <vuln:summary>Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3372">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1::alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1::beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3372</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.890-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-29T12:31:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-55.html">http://www.mozilla.org/security/announce/2009/mfsa2009-55.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=500644">https://bugzilla.mozilla.org/show_bug.cgi?id=500644</vuln:reference>
        </vuln:references>
        <vuln:summary>Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3373">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:alpha" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta2</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1::alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1::beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3373</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.907-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T08:58:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-56.html">http://www.mozilla.org/security/announce/2009/mfsa2009-56.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=511689">https://bugzilla.mozilla.org/show_bug.cgi?id=511689</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3374">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3374</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.937-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T09:02:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-57.html">http://www.mozilla.org/security/announce/2009/mfsa2009-57.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=505988">https://bugzilla.mozilla.org/show_bug.cgi?id=505988</vuln:reference>
        </vuln:references>
        <vuln:summary>The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."</vuln:summary>
    </entry>
    <entry id="CVE-2009-3375">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3375</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.953-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T09:05:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-61.html">http://www.mozilla.org/security/announce/2009/mfsa2009-61.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=503226">https://bugzilla.mozilla.org/show_bug.cgi?id=503226</vuln:reference>
        </vuln:references>
        <vuln:summary>content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3376">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1::alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1::beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3376</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:00.983-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T09:21:57.467-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T09:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-16" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=511521">https://bugzilla.mozilla.org/show_bug.cgi?id=511521</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-62.html">http://www.mozilla.org/security/announce/2009/mfsa2009-62.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3377">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3377</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T09:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=512327">https://bugzilla.mozilla.org/show_bug.cgi?id=512327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html">http://www.mozilla.org/security/announce/2009/mfsa2009-63.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=515376">https://bugzilla.mozilla.org/show_bug.cgi?id=515376</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3378">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3378</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.017-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T09:34:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html">http://www.mozilla.org/security/announce/2009/mfsa2009-63.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=500311">https://bugzilla.mozilla.org/show_bug.cgi?id=500311</vuln:reference>
        </vuln:references>
        <vuln:summary>The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3379">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3379</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.047-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T09:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=500254">https://bugzilla.mozilla.org/show_bug.cgi?id=500254</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html">http://www.mozilla.org/security/announce/2009/mfsa2009-63.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=515889">https://bugzilla.mozilla.org/show_bug.cgi?id=515889</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=507167">https://bugzilla.mozilla.org/show_bug.cgi?id=507167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=501279">https://bugzilla.mozilla.org/show_bug.cgi?id=501279</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=499512">https://bugzilla.mozilla.org/show_bug.cgi?id=499512</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3380">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3380</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.077-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T09:51:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=522030">https://bugzilla.mozilla.org/show_bug.cgi?id=522030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=514776">https://bugzilla.mozilla.org/show_bug.cgi?id=514776</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=509602">https://bugzilla.mozilla.org/show_bug.cgi?id=509602</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=509244">https://bugzilla.mozilla.org/show_bug.cgi?id=509244</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=508927">https://bugzilla.mozilla.org/show_bug.cgi?id=508927</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=497013">https://bugzilla.mozilla.org/show_bug.cgi?id=497013</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=489925">https://bugzilla.mozilla.org/show_bug.cgi?id=489925</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=454872">https://bugzilla.mozilla.org/show_bug.cgi?id=454872</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3381">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3381</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.093-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T10:01:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=516709">https://bugzilla.mozilla.org/show_bug.cgi?id=516709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=513394">https://bugzilla.mozilla.org/show_bug.cgi?id=513394</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=508057">https://bugzilla.mozilla.org/show_bug.cgi?id=508057</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=503196">https://bugzilla.mozilla.org/show_bug.cgi?id=503196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=502168">https://bugzilla.mozilla.org/show_bug.cgi?id=502168</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3382">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3382</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.127-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T10:07:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=514960">https://bugzilla.mozilla.org/show_bug.cgi?id=514960</vuln:reference>
        </vuln:references>
        <vuln:summary>layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3383">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3383</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.140-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T10:15:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=518675">https://bugzilla.mozilla.org/show_bug.cgi?id=518675</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=510987">https://bugzilla.mozilla.org/show_bug.cgi?id=510987</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3626">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:perl:perl:5.10.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:perl:perl:5.10.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3626</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.170-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T10:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3023">ADV-2009-3023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://perl5.git.perl.org/perl.git/commit/0abd0d78a73da1c4d13b1c700526b7e5d03b32d4">http://perl5.git.perl.org/perl.git/commit/0abd0d78a73da1c4d13b1c700526b7e5d03b32d4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225">https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53939">perl-utf8-expressions-dos(53939)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36812">36812</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/59283">59283</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/10/23/8">[oss-security] 20091023 CVE-2009-3626 assigment notification - Perl - perl-5.10.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1023077">1023077</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37144">37144</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://rt.perl.org/rt3/Ticket/Attachment/617489/295383/">http://rt.perl.org/rt3/Ticket/Attachment/617489/295383/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://rt.perl.org/rt3/Public/Bug/Display.html?id=69973">http://rt.perl.org/rt3/Public/Bug/Display.html?id=69973</vuln:reference>
        </vuln:references>
        <vuln:summary>Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3627">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.00" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.4" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.41" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.42" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.5" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:1.6" />
                <cpe-lang:fact-ref name="cpe:/a:derrick_oswald:html-parser:3.54" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.2</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.1</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.00</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.4</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:3.54</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.3</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.6</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.42</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.5</vuln:product>
            <vuln:product>cpe:/a:derrick_oswald:html-parser:1.41</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3627</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.203-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T10:25:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225">https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3022">ADV-2009-3022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36807">36807</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/10/23/9">[oss-security] 20091023 CVE-2009-3627 assignment notification - HTML-Parser-3.63</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=530604">https://bugzilla.redhat.com/show_bug.cgi?id=530604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53941">htmlparser-decodeentities-dos(53941)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37155">37155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c">http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c</vuln:reference>
        </vuln:references>
        <vuln:summary>The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3638">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-ow2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-pre9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24::-ow1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::x86" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.1" />
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.35" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.41" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.42" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.43" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.44" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.38" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.39" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.40" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.2.27.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.61" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.62" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.52" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.51" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.50" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.49" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.48" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.47" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.46" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.45" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.60" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.59" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.58" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.57" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.56" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.55" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.54" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.53" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc4:x86_32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc8-kk" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:git7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:git1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc2_git7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc7-git6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.35" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.8.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.8.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23::-ow2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:git1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:git7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::x86</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.2</vuln:product>
            <vuln:product>cpe:/a:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.2.27.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.35</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.61</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.60</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.62</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.52</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.51</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.50</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.56</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.55</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.54</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.53</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.59</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.57</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.58</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.35</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.38</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.39</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.49</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.48</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.47</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.46</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.40</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.41</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc7-git6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.44</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.45</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.42</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.43</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc2_git7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37:-rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23::-pre9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29:-rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29:-rc1</vuln:product>
            <vuln:product>cpe:/a:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.24::-ow1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc4:x86_32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.2.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc8-kk</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3638</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.233-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T11:20:35.953-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T11:05:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=530515">https://bugzilla.redhat.com/show_bug.cgi?id=530515</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53934">linux-kernel-supportedcpuid-code-execution(53934)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36803">36803</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc4">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.4">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125632898507373&amp;w=2">[oss-security] 20091023 Re: CVE request: kvm: integer overflow in kvm_dev_ioctl_get_supported_cpuid()</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125628917011048&amp;w=2">[oss-security] 20091023 CVE request: kvm: integer overflow in kvm_dev_ioctl_get_supported_cpuid()</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6a54435560efdab1a08f429a954df4d6c740bddf">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6a54435560efdab1a08f429a954df4d6c740bddf</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3640">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-ow2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-pre9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24::-ow1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::x86" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.1" />
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.35" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.41" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.42" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.43" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.44" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.38" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.39" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.40" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.2.27.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.61" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.62" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.52" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.51" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.50" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.49" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.48" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.47" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.46" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.45" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.60" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.59" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.58" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.57" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.56" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.55" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.54" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.53" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc4:x86_32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc8-kk" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:git7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:git1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc2_git7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc7-git6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.35" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.8.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31:rc8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.8.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23::-ow2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:git1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:git7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::x86</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.2</vuln:product>
            <vuln:product>cpe:/a:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.2.27.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.35</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.61</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.60</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.62</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.52</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.51</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.50</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.56</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.55</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.54</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.53</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.59</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.57</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.58</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.35</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.38</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.39</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31:rc8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.49</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.48</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.47</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.46</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.40</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.41</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc7-git6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.44</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.45</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.42</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.43</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc2_git7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37:-rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23::-pre9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29:-rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29:-rc1</vuln:product>
            <vuln:product>cpe:/a:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.24::-ow1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc4:x86_32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.2.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc8-kk</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3640</vuln:cve-id>
        <vuln:published-datetime>2009-10-29T10:30:01.250-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-10-30T11:21:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53947">kernel-updatecr8intercept-dos(53947)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36805">36805</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125640417219385&amp;w=2">[oss-security] 20091024 Re: CVE request: kvm: update_cr8_intercept() NULL pointer dereference</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125626965020571&amp;w=2">[oss-security] 20091023 CVE request: kvm: update_cr8_intercept() NULL pointer dereference</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=88c808fd42b53a7e01a2ac3253ef31fef74cb5af">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=88c808fd42b53a7e01a2ac3253ef31fef74cb5af</vuln:reference>
        </vuln:references>
        <vuln:summary>The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3828">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:everfocus:edr1600_dvr" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:everfocus:edr1600_dvr</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3828</vuln:cve-id>
        <vuln:published-datetime>2009-10-30T15:30:00.217-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-02T07:43:06.233-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-11-02T07:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/53909">everfocus-authentication-sec-bypass(53909)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/507373/100/100/threaded">20091022 Everfocus EDR1600 remote authentication bypass</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/59139">59139</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37108">37108</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/fulldisclosure/2009/Oct/293">20091022 Everfocus EDR1600 remote authentication bypass</vuln:reference>
        </vuln:references>
        <vuln:summary>The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3549">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2.0" />
                    <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2.1" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/h:sun:sparc" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2.0</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3549</vuln:cve-id>
        <vuln:published-datetime>2009-10-30T16:30:00.250-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-02T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-11-02T07:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html">http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3061">ADV-2009-3061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36846">36846</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/54016">wireshark-dissectpaltalk-dos(54016)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/security/wnpa-sec-2009-07.html">http://www.wireshark.org/security/wnpa-sec-2009-07.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37175">37175</vuln:reference>
        </vuln:references>
        <vuln:summary>packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3550">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.10" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.11" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.12" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.13" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.14" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.2" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.3" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.4" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.5" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.6" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.7" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.8" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.9" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.5</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.6</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.3</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.4</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.9</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.7</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.8</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.7</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.8</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2.0</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.5</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2.1</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.6</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.9</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.0</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.13</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.3</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.12</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.4</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.2</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.1</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.14</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.0.2</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.10</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:0.10.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3550</vuln:cve-id>
        <vuln:published-datetime>2009-10-30T16:30:00.280-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-02T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-11-02T09:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html">http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/docs/relnotes/wireshark-1.0.10.html">http://www.wireshark.org/docs/relnotes/wireshark-1.0.10.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/54017">wireshark-dcerpcnt-dos(54017)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/security/wnpa-sec-2009-08.html">http://www.wireshark.org/security/wnpa-sec-2009-08.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/security/wnpa-sec-2009-07.html">http://www.wireshark.org/security/wnpa-sec-2009-07.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3061">ADV-2009-3061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36846">36846</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37175">37175</vuln:reference>
        </vuln:references>
        <vuln:summary>The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3551">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2.0</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2</vuln:product>
            <vuln:product>cpe:/a:wireshark:wireshark:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3551</vuln:cve-id>
        <vuln:published-datetime>2009-10-30T16:30:00.313-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-02T07:49:31.377-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-11-02T07:45:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html">http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3061">ADV-2009-3061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36846">36846</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/54018">wireshark-negprotresponse-dos(54018)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.wireshark.org/security/wnpa-sec-2009-07.html">http://www.wireshark.org/security/wnpa-sec-2009-07.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/37175">37175</vuln:reference>
        </vuln:references>
        <vuln:summary>Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3623">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-ow2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-pre9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24::-ow1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::x86" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.1" />
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.35" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.41" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.42" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.43" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.44" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.38" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.39" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.40" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.2.27.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.61" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.62" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.52" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.51" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.50" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.49" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.48" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.47" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.46" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.45" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.60" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.59" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.58" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.57" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.56" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.55" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.54" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.53" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc4:x86_32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc8-kk" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:git7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:git1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29:rc2_git7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc7-git6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.29.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.35" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.30:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.8.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.31.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.8.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23::-ow2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21::-pre7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:git1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:git7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::x86</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.35.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.2</vuln:product>
            <vuln:product>cpe:/a:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.2.27.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.35</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.61</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.60</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.62</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.52</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.51</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.50</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.56</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.55</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.54</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.53</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.59</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.57</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.58</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18::pre-8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.35</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.38</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.39</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.49</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.48</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.47</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.46</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.40</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.41</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc7-git6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.44</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.45</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.42</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.43</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27::-pre5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc2_git7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29.rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37:-rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23::-pre9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29:-rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29:-rc1</vuln:product>
            <vuln:product>cpe:/a:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.31.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.24::-ow1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.30:rc4:x86_32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31:-rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.2.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.29:rc8-kk</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.37.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-3623</vuln:cve-id>
        <vuln:published-datetime>2009-10-30T16:30:00.343-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-02T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-11-02T09:56:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=530269">https://bugzilla.redhat.com/show_bug.cgi?id=530269</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.2">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125624036516377&amp;w=2">[oss-security] 20091022 Re: CVE request: kernel: nfsd4: fix null dereference creating nfsv4 callback client</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=oss-security&amp;m=125618753029631&amp;w=2">[oss-security] 20091022 CVE request: kernel: nfsd4: fix null dereference creating nfsv4 callback client</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=886e3b7fe6054230c89ae078a09565ed183ecc73">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=886e3b7fe6054230c89ae078a09565ed183ecc73</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=80fc015bdfe1f5b870c1e1ee02d78e709523fee7">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=80fc015bdfe1f5b870c1e1ee02d78e709523fee7</vuln:reference>
        </vuln:references>
        <vuln:summary>The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.</vuln:summary>
    </entry>
    <entry id="CVE-2009-3722">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.21::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.19::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.29:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-ow2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.23::-pre9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24::-ow1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.27::-pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::x86" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.18::pre-4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.35.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.34.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.33.1" />
                <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31:-rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.37:-rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.9" />
                <cpe-lang:fact-ref name="